August 2026 Patch Tuesday: Microsoft fixes over 420 flaws

Microsoft’s August 2026 Patch Tuesday has landed as one of the year’s largest security updates, closing out 421 CVEs, including more than 40 rated critical, according to Microsoft’s Security Update Guide and multiple security vendors tracking the release. The update is headlined by an actively exploited kernel driver flaw, a publicly disclosed elevation-of-privilege bug tied to a researcher long at odds with Microsoft, and a SharePoint remote code execution chain flagged by Rapid7.
Lazarus Group exploits kernel driver zero-day
The most urgent fix is CVE-2026-68820a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver underpinning the Windows Sockets API. Microsoft says a locally authenticated attacker can trigger a race condition through a specially crafted application to gain SYSTEM privileges without user interaction. Check Point Research reported that North Korea’s Lazarus Group exploited the flaw as part of its Operation Dream Job campaign, using fake recruiter outreach and a trojanized PDF viewer to deploy Troy, a new backdoor, before escalating privileges and installing an updated version of its FudModule kernel-mode rootkit. The activity has focused on defense, aerospace, and aviation organizations across Europe, India, and Brazil. CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog, with a remediation deadline of August 25.
A public feud over LegacyHive
Microsoft also patched CVE-2026-62832an elevation-of-privilege flaw in the Windows User Profile Service. The bug lets an authenticated attacker who holds credentials for another local account force the service to load that account’s registry hive, potentially an administrator’s, granting unauthorized access to that data and administrator rights. Microsoft credited the discovery to an anonymous researcher, though the technical details match LegacyHive, a proof of concept the pseudonymous researcher Nightmare Eclipse published just hours after July’s Patch Tuesday. Because working exploit code had already circulated publicly, Microsoft assessed the flaw as more likely to be exploited more broadly.
Rapid7 completes a SharePoint RCE chain
Rounding out the release is CVE-2026-63520a SharePoint Server remote code execution vulnerability rooted in unsafe .NET type instantiation within Business Connectivity Services. Rapid7 disclosed it alongside Microsoft as the second half of an exploit chain built for Pwn2Own Berlin. Paired with CVE-2026-55040, the JWT authentication bypass Rapid7 disclosed in July, the two flaws let an unauthenticated attacker execute code on a vulnerable SharePoint server with the privileges of its service account without any credentials.
I’m a tech editor and journalist with more than 20 years of experience covering smartphones, AI, gaming hardware, and emerging technology. I’m passionate about making complex topics clear, engaging, and relevant—especially when they shape how we live, work, and play.
I’m also an author with a love for psychological thrillers, horror, and honest, emotionally driven storytelling. My books include Drowning, 3:33 a.m., The Midnight Murderer, Keystrokes of Vengeance, and Life’s Too Short For This Sh!t!.
Whether I’m writing about technology or fiction, my goal is always to connect with readers, spark thought, and leave a lasting impression. Inspired by my daughters and shaped by years of media experience, I bring curiosity and purpose to everything I write.





